Skip to content

Methodology & About

News Agent is a curated cyber-threat and M&A intelligence feed compiled from public reporting for situational awareness. It is produced for private-equity operators and their portfolios. This page explains how to read it โ€” and, importantly, what it does and does not assert.

Claims are not confirmed breaches

A large share of the victim data on this site originates from ransomware / extortion groups' own data-leak sites (DLS). A listing there is a claim by the attacker, not a confirmed breach. Groups recycle, inflate, and re-post entries. We publish these claims because tracking them is standard cyber-threat-intelligence practice โ€” but we frame them as claims:

  • We say an organisation was listed on \<actor>'s leak site or claimed by \<actor>.
  • We do not say it was "breached" or "hacked" unless the organisation (or an authoritative source such as CISA, FBI, or Mandiant) has confirmed it.
  • Verify before acting. Treat an unverified claim as a lead to investigate, not a fact.

Confidence flags

Every tracked record carries a confidence flag:

๐ŸŸฉ FirmCompany-confirmed or corroborated by an authoritative source (published breach notice, regulator filing, government advisory).
๐ŸŸจ PartialSome corroboration (multiple reputable outlets) but not fully confirmed by the victim.
๐ŸŸฅ Estimated / unverifiedAn attacker claim (typically a DLS listing) with no independent confirmation. Verify before treating as a breach.

Severity flags (briefings)

๐Ÿ”ด CriticalImmediate, high-impact โ€” active exploitation, large-scale exposure, or strategic significance.
๐ŸŸก HighMaterial and worth attention this week.
๐ŸŸข MediumNotable context; lower urgency.

Signals confidence (ICD-203)

The Signals section tracks emerging trends and behaviour shifts โ€” not confirmed news โ€” so it uses a different model than the claim-verification flags above: analytic confidence, adapted from the US intelligence community's ICD-203 standard. It grades how much we trust the judgment, not whether an individual fact is verified.

๐ŸŸฉ High confidenceMultiple independent, named sources; corroborated by distinct data points, not a single echoed narrative.
๐ŸŸจ Moderate confidenceGrowing corroboration, but sources still trace back to a small cluster of overlapping reporting, or lack independent data.
๐ŸŸฅ Low confidenceA single source or unverified forum chatter โ€” a lead worth watching, not yet a pattern.

Each signal also carries a one-line words-of-estimative-probability judgment (e.g. "likely", "roughly even chance") about where the trend goes next โ€” a separate axis from confidence in the current read. Forum/sentiment sources (Reddit, Hacker News) are treated as anecdotal by default: a single post is ๐ŸŸฅ Low on its own; confidence upgrades only once corroborated by a second independent thread or a press source.

Signal lifecycle

Signals are living records, not one-off entries. Watching (first observation) โ†’ Strengthening or Fading (as corroboration grows or evidence goes quiet) โ†’ Confirmed-trend or Archived/Confidence-decayed. There is no "wrong" signal here โ€” only signals whose confidence rises or falls with the evidence. Moving one to the Archive records that corroboration stopped accumulating or confidence declined, not that the original observation was incorrect. Resolved signals move to the Archive โ€” never deleted โ€” and are rechecked roughly weekly for resurgence, since a decayed signal sometimes comes back.

Cross-domain convergence

A signal that co-occurs with an item in the same window's Geopolitics section or Threat Actor & Campaign Activity โ€” pointing at the same country or sector โ€” is flagged with a โšก badge. The convergence across independent domains is often the actual early-warning signal; no single domain alone would have surfaced it.

Threat Level composite

The home page's Threat Level tile is a 0โ€“100 weighted composite of three components, each computed from the data (never hardcoded): breach severity (today's critical-flagged items, weight 0.5), victim volume (disclosed victims over the trailing 30 days, weight 0.3), and actor concentration (the most-active actor's share of that 30-day volume, weight 0.2), banded into GUARDED / ELEVATED / HIGH. Like the Signals confidence model, these weights and thresholds are editorial judgment, not a scientific measure โ€” calibrated by reviewing the site's own briefing history so the bands actually discriminate, not derived from an academic index. The methodology is versioned (THREAT_LEVEL_VERSION in build_site.py); a coefficient or threshold change bumps the version and gets a line here.

Sourcing standard

Every item is attributed with at least one clickable link, and figures are corroborated across independent sources before publication. We prefer primary sources โ€” vendor releases, SEC 8-Ks, and government advisories โ€” over aggregators, and file M&A deals by announcement date and breaches by disclosure date. Where a figure cannot be corroborated, we say so rather than inventing it. See the Sources page for the tracked source list and its live reachability status.

Scope

Cybersecurity M&A from 2026 onward and notable global incidents, with the US and Europe prioritised. APT / nation-state victims are listed only on authoritative attribution, never on group claims alone.


Feedback: intel@bluesec.io. This is a staging preview โ€” a prototype for evaluation, not the production feed.